A blind XML External Entity (XXE) injection in the...
Critical severity
Unreviewed
Published
Sep 9, 2025
to the GitHub Advisory Database
•
Updated Sep 9, 2025
Description
Published by the National Vulnerability Database
Sep 9, 2025
Published to the GitHub Advisory Database
Sep 9, 2025
Last updated
Sep 9, 2025
A blind XML External Entity (XXE) injection in the OpenMessaging webservice in TecCom TecConnect 4.1 allows an unauthenticated attacker to exfiltrate arbitrary files to an attacker-controlled server. TecConnect 4.1 is considered end-of-life as of December 2023. Users are advised to upgrade to TecCom Connect 5.
References